Repository navigation
feat: add jev support - #53
Merged
Merged
Conversation
joshlarsen
enabled auto-merge (squash)
October 5, 2026 11:09
matslofva
approved these changes
Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds opt-in advisory secret classification through TypeSafe's Jev model to both the CLI and Go library. After regex detection, Poltergeist can enrich findings with a likelihood that the matched value is an authentic secret, using its exact location and nearby source as evidence. Classification never suppresses findings, changes entropy filtering, or changes finding-based exit codes: a value labeled
likely_dummyis still reported as a finding.CLI and report changes
-classify, usingTYPESAFE_API_KEYfor authentication. Classification is disabled by default; setting the environment variable alone does not enable it.-classify-timeout(default10s),-classify-max-candidates(default1000), and opt-in-classify-cache-dir.-low-entropyalso makes reported low-entropy matches eligible;-classify-all, when used with-classify, includes low-entropy candidates even when the report hides them.TYPESAFE_API_KEY='your-api-key' poltergeist -classify -format json ./sourceEnabling classification sends raw matched values, bounded surrounding source, relative paths, and rule identifiers/names to TypeSafe, including when report redaction is enabled.
Library and classification semantics
Scanner.Classification,ClassificationOptions, an injectableCandidateClassifierinterface, classification batch/result types, andNewJevClassifierwith configurable credentials, versioned model, endpoint, HTTP client, and optional cache.ScanDirectoryContext; the existingScanDirectoryAPI remains available and enriches findings when configured. Detection cancellation returns an error; an enrichment deadline returns findings with explicit unscored statuses.jev-1.13.0and the policy tosecret-authenticity-v1; unversioned model aliases are rejected.real_secret_probabilityin[0, 1], labeledlikely_realat or above0.90,likely_dummyat or below0.10, anduncertainotherwise. Results carry model, policy, source (live,cache, ormemory), and context-truncation metadata.scored,skipped, anderror, with reason codes for unscored findings. Missing probabilities are omitted rather than treated as zero.Bounded context and execution
Jev client and caching
Documentation and validation
docs/classification.mdcovering usage, transmitted data, score interpretation, limits, caching, reproducibility, and library integration; links it from the README.